Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 05:16:16 PM

Pages: [1]   Go Down
  Print  
Author Topic: suggestion about script vulnerabilities  (Read 1639 times)
jimlongo
Intergalactic Superstar
*****
Offline Offline

Posts: 125



WWW
« on: December 30, 2009, 10:34:57 AM »

i recently had my site affected by the placement of various php files onto my server.  These files "merely" spoofed googlebot into seeing different content than the public viewed, thus messing up my keywords temporarily.  Luckily I noticed it fairly quickly and was able to recover from this with the assistance of LP Support. 

In the process of discussing this attack with a support agent it was brought to my attention that a WordPress Fantastico installation which I had just recently installed was out of date and was used as the entry in this exploit. 

Now I'm sure that the many LP clients who have installed WP aren't aware of this vulnerability.  My suggestion is that LP should think about Security Bulletin emails to all clients whenever there is an affected installation that needs to be updated.  The Fantastico update took all of a minute to do, and it would have saved me a lot of time if there had been some kind of public notification of the availability of the update.

I respect the fact that it's the clients responsibility to keep scripts up to date, but at least the monthly Lunarpages email (unless I missed it) would be a good place to advertise these security issues, or as I said a separate Security Bulletin, or at least a message on the Security forums.  I apologize if there was such a notice and I missed it, but if that's the case then obviously it could have been made to be more noticeable.

Thanks.

Logged

Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #1 on: December 30, 2009, 11:30:59 AM »

I'll see what I can come up with - the main problem would be monitoring all the scripts out there, cause if you got a few, then you know one person would be mad cause you left out the script they used.  Let me see what I can figure out.  Thumbs Up
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #2 on: December 30, 2009, 11:56:00 AM »

Found two good resources - (credit goes to Tristan) http://secunia.com/advisories/historic/ and the search page for it - http://secunia.com/advisories/search/?search=wordpress

I might see if I can also do some type of security alert or roundup via the monthly newsletter too. Smile

If anybody else has suggestions or resources, feel free to share!

Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: